2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2020-21101" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2021-04-29T17:15:08.877" ,
"lastModified" : "2021-05-10T19:02:37.633" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code."
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de tipo Cross Site Scripting en Screenly screenly-ose todas las versiones, incluyendo la v1.8.2 (25-09-2019-Screenly-OSE-lite.img), en la p\u00e1gina \"Add Asset\" por medio de la manipulaci\u00f3n de un campo \"URL\", lo que podr\u00eda permitir un usuario malicioso remoto ejecutar c\u00f3digo arbitrario"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 2.7
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:S/C:N/I:P/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 3.5
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 6.8 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.9:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "7CFB3738-DE0F-441B-A039-EAB2E42B3EF0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.9.1:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "D8F7643E-4471-42E8-9B3C-49B1A112192E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.10:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "F247D15B-295C-47B6-A9BA-3A0E2A7539BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.11:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "BC608737-F5A3-45A9-91A8-BC3701935FEC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.12:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "78965B93-25A8-4CE3-A4F1-7EA423729646"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.12.1:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "1CD6D5ED-B489-416B-BAA7-A08AA26EE2E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.13:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "7528E8E4-F7D0-43A1-8396-40250EA06E7B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.14:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "0C8484A1-29B9-42B2-9575-2B4046441038"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.15:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "3B012DDE-AD03-4FF0-9D69-C4D3B2A5DA00"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.15.1:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "15C2FCE5-2DBB-48D5-BDC2-E29D0EDCD8F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.16:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "B17538D4-9B81-400D-AC99-C6B61C84124F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.17:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "FEFAC1AA-61FE-4FA8-8F5D-BFCF7DBCD90D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.18:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "E15080B4-6280-44DA-B5FA-8C75E354C702"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.18.1:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "20C78F35-0B09-4676-9C71-3D37FFD42250"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:screenly:screenly:0.18.2:*:*:*:ose:*:*:*" ,
"matchCriteriaId" : "00E743C8-B290-4C3F-829E-03007AF4F7B0"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/Screenly/screenly-ose/issues/1254" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
}
]
}